Domains: 000webhostapp.com niscarea.com gosiclass.com Sub Domains: 00701111.000webhostapp.com gosiweb.gosiclass.com URLs: http://gosiweb.gosiclass.com/m/gnu/convert/html/com/list.php?query=6 https://niscarea.com/in.php?cn=[base64]&fn=[DateTime] md5: f35b05779e9538cec363ca37ab38e287 364d4fdf430477222fe854b3cd5b6d40 71db2ae9c36403cec1fd38864d64f239 sha1: 5c7b2705155023e6e438399d895d30bf924e0547 d4fa57f9c9e35222a8cacddc79055c1d76907fb9 b5224224fdbabdea53a91a96e9f816c6f9a8708c sha256: da79eea1198a1a10e2ffd50fd949521632d8f252fb1aadb57a45218482b9fd89 c62677543eeb50e0def44fc75009a7748cdbedd0a3ccf62f50d7f219f6a5aa05 e8000ddfddbe120b5f2fb3677abbad901615d1abd01a0de204fade5d2dd5ad0d CVEs: CVE-2024-27199 CVE-2024-27198 File Names Found Outside Quotes: Reg.exe list.php Introduction.html HH.exe sys.txt Incomplete.html use.html in.php info.txt 9583423.bat 2034923.bat CMD.exe weapons.html home.html 1295049.bat review.html purpose.html File Names Found Inside Quotes: MXFhejJ3c3gzZWRjA.vbs sys.txt use.html in.php 9583423.bat 2034923.bat weapons.html review.html .000webhostapp.c 1295049.bat home.html purpose.html Introduction.html HH.exe Incomplete.html CMD.exe info.txt Reg.exe list.php MXFhejJ3c3gzZWRjA.dat gosiweb.go Registry: HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run